Nothing ruins a quiet afternoon like apt autoremove deciding a package you rely on is surplus. apt-mark shows which packages APT treats as manual or automatic, lets you change that, and can hold a package back when an upgrade must wait. Allow about 10 minutes.
The examples target the installed APT 2.8.3 on Ubuntu 24.04. You need a shell account that can read the package state; changing a live package mark or hold normally needs root privileges.
Confirm which executable will run and which version supplies its behaviour. This only reads local information and does not need sudo:
$ command -v apt-mark
/usr/bin/apt-mark
$ apt-mark --version
apt 2.8.3 (amd64)
The version matters because package-management interfaces can gain or change details over time. This guide follows the local apt-mark(8) manual, whose source is APT 2.8.3.
Checkpoint: if command -v apt-mark returns nothing, stop and repair the APT installation before copying the later commands. Do not download a replacement script called apt-mark.
APT records a package you explicitly requested as manual. Dependencies pulled in to satisfy that request are normally automatic. An automatic package becomes a removal candidate when no manually installed package still depends on it. The mark is not the same thing as whether the package is currently installed.
List all manual packages, or narrow the output by naming packages:
$ apt-mark showmanual apt
apt
$ apt-mark showauto apt
apt
The second command prints a package only if this host marks it automatic. Output is host-specific, and a blank result is a valid result. Without a package argument, both showmanual and showauto print a potentially long list, one package per line.
Warning: an automatic mark is not an instruction to remove a package immediately. It is input to APT's dependency calculation. Check what APT proposes with a dry run before accepting a removal:
$ apt-get -s autoremove
The -s option belongs to apt-get, not apt-mark. Review the complete simulated list. If a package you need appears there, cancel the real operation and mark that package manual.
Use manual when a package is part of your intended system but no other manual package holds it in place any more. Replace PACKAGE_NAME with an installed package name you have checked:
$ sudo apt-mark manual PACKAGE_NAME
PACKAGE_NAME was already set to manually installed.
If the mark changed, APT reports that it was set to manually installed. The exact wording can vary, so rely on a zero exit status and a follow-up query:
$ apt-mark showmanual PACKAGE_NAME
PACKAGE_NAME
This changes package metadata, not the package files. It does not install a missing package, upgrade it, or remove its dependencies. The reversal is explicit:
$ sudo apt-mark auto PACKAGE_NAME
$ apt-mark showauto PACKAGE_NAME
PACKAGE_NAME
Warning: marking a package automatic can make it eligible for a future autoremove if no manual package depends on it. Simulate that operation before allowing it to remove anything:
$ apt-get -s autoremove
Recovery: if the result is wrong, restore the manual mark with sudo apt-mark manual PACKAGE_NAME. Keep the package name exact; do not paste a full shell command into the package argument.
apt-mark stores automatic-package state in /var/lib/apt/extended_states by default. The --file option, written as -f=FILENAME, reads and writes another state file instead. That makes it a safe way to learn the command without touching the live marks.
Make a temporary copy, then use it for both the change and the verification:
$ state_file=$(mktemp /tmp/apt-mark-state.XXXXXX)
$ cp --preserve=mode,timestamps /var/lib/apt/extended_states "$state_file"
$ apt-mark -f="$state_file" showmanual apt
apt
$ apt-mark -f="$state_file" auto apt
apt set to automatically installed.
$ apt-mark -f="$state_file" showauto apt
apt
$ rm -- "$state_file"
The copied file is disposable. The example deliberately uses apt only to show the state transition in isolation; it does not alter the live system.
Tip: if your account cannot read the default state file, create the copy with appropriate read access or use a package-state backup from your administrator. Do not replace /var/lib/apt/extended_states by hand.
A hold is a stronger operational boundary than a manual or automatic mark. It tells APT not to automatically install, upgrade, or remove the held package. Use it when an upgrade needs investigation or coordination. This changes live package-management state and needs root privileges:
$ sudo apt-mark hold PACKAGE_NAME
PACKAGE_NAME set on hold.
$ apt-mark showhold PACKAGE_NAME
PACKAGE_NAME
Before you hold, check that you are naming the intended package and record why the hold exists. A hold can make a routine upgrade look incomplete, so put it in the handover or maintenance notes. It does not stop a person deliberately changing package state through every possible tool, and it does not freeze unrelated dependencies.
When the reason has gone, remove the hold. This is the recovery command, and it also needs root:
$ sudo apt-mark unhold PACKAGE_NAME
Canceled hold on PACKAGE_NAME.
$ apt-mark showhold PACKAGE_NAME
Checkpoint: the final query should print no package name. Do not treat silence as proof if the command returned an error; check its exit status and spelling first.
The install, remove, and purge subcommands set dpkg selection states. They schedule a selection for a front-end such as apt-get dselect-upgrade; they are not the same as immediately installing, removing, or purging a package.
Inspect a selection before changing it. The show commands accept an optional package filter:
$ apt-mark showinstall PACKAGE_NAME
$ apt-mark showremove PACKAGE_NAME
$ apt-mark showpurge PACKAGE_NAME
A blank result means that package has no matching selection. If you need to schedule a change, read the resulting selection back immediately and record the intended application command.
Warning: treat purge as destructive. It can remove package configuration when the selection is later applied. Do not use it as a synonym for ordinary removal, and do not run a scheduled change on a production machine without a backup and a reviewed package list.
showauto is a clue, not proof that removal is safe.apt-mark showhold PACKAGE_NAME. Remove an old hold only after confirming that the upgrade is wanted.sudo. Do not make the state file world-writable.-f for the live default only when that is intentional. For experiments, verify the temporary file path before running a write command.apt-mark version and executable.apt-get -s autoremove.--file rehearsal, the real marks are unchanged.